← العودة للجدول
CVE-2026-82746
CVE-2026-82746 — Missing Authorization vulnerability in ash-project ash allows an actor to update
📅 2026-09-01
🟠 High 🔥 No NVD Vulnerability Vulnerability

📋 الوصف الكامل

Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a data-layer update_many, for example a SQL MERGE) whenever an atomic strategy is used and the data layer supports it. Ash.Actions.Update.UpdateMany (lib/ash/actions/update/update_

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-82746

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.29.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←